Corporate Security Engineer

Docker
Docker
Spain (Remote)RemoteCompetitivoPublicado hace 1 mesRemoto: Remoto
Patrocina visa🇬🇧Inglés requeridoFulltime

Anuncio original

Docker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 billion container image pulls. From solo founders to the world's largest companies, developers rely on Docker to build, share, and run their applications across our suite of products including Docker Desktop, Docker Hub, and Docker Scout.

We are a globally distributed, remote-first team building the tools that define how software gets built and delivered. As AI agents redefine software development, Docker is at the center of that shift, providing the sandboxed environments, verified images, and secure infrastructure that make autonomous workflows trustworthy by default.

As a Corporate Security Engineer, you will be the primary technical owner of Docker's identity infrastructure, endpoint security, SaaS governance, and device compliance programs. You will work closely with the IT Operations, and GRC teams to design and implement the controls that keep Docker secure.

This role offers the opportunity to build and mature security programs at a company whose products are trusted by millions of developers worldwide. You'll work in a technically challenging environment where your security expertise directly impacts both Docker's platform and the broader container ecosystem.

Responsibilities:

  • Own and continuously improve Docker's Identity and Access Management infrastructure, including SSO, MFA enforcement, lifecycle management, and access governance

  • Discover, map inventory and conduct security reviews on third-party integrations and drive security improvements across our SaaS application ecosystem

  • Secure and harden our core collaboration as well as documentation platforms, including email, document sharing, and communication tools

  • Define and enforce device compliance policies across our corporate device fleet; own the end-to-end compliant device experience

  • Mature a Zero Trust security model across corporate infrastructure, enforcing conditional access based on identity

  • Establish and maintain an approved application governance program across desktop, browser, developer tooling, and third-party AI services, with appropriate monitoring and risk-based controls

  • Contribute to the team's incident response capability, bringing corporate IT and identity expertise to investigations and remediation efforts

  • Design and deploy canaries across our endpoint fleet, for increased visibility and early-warning capabilities

  • Participate in the Security team on-call rotation by managing detection and response to security events

  • Own and continuously improve employee lifecycle security processes, ensuring robust controls at both onboarding and offboarding

  • Maintain IT security evidence and documentation supporting compliance with SOC2 and ISO ISO 27xxx

  • Take part in on-call rotation for your team; respond to incidents, debug production issues, and drive continuous improvement of system reliability

Qualifications

  • 6+ years in IT systems engineering with emphasis on automation, and hands-on experience in identity access management, and security best practices

  • Deep hands-on expertise with Enterprise IdP (SSO, MFA, lifecycle management, groups, API automation)

  • Strong experience securing Google Workspace at an admin level

  • Experience with MDM solutions and endpoint hardening

  • Solid understanding of OAuth, SAML, OIDC, and modern identity and access patterns

  • Experience governing SaaS applications at scale: inventory, risk assessment, integration audits

  • Scripting or automation skills (Golang, Python, Bash, Terraform, or similar) for API integration work

  • Ability to write and own technical design documents and risk assessments

  • Strong cross-functional communication - able to work effectively with GRC, IT, legal, and non-technical stakeholders

  • Experience with compliance frameworks such as SOC2 or ISO 27xxx

Bonus:

  • Experience with Zero-Trust Network Access solutions (ZTNA) and Endpoint Detection and Response (EDR) tooling

  • Familiarity with canary/deception-based detection techniques

  • Experience implementing Just-in-Time (JIT) access patterns and identity-as-code practices

  • Experience with implementing and rolling out Data Leak Prevention (DLP) solutions

What to expect

First 30 days:

  • Meet the Security, IT, and GRC teams

  • Build a clear picture of Docker's tooling stack, security posture, and existing gaps

  • Audit current identity, endpoint, and SaaS configurations to form an initial risk-prioritized view of the landscape

  • Get up to speed on the Corporate IT Security backlog and begin contributing to active work

  • Gain access to team owned systems, and internal documentation

  • Complete security awareness training and compliance onboarding

  • Familiarize oneself with team workflows and processes

  • Shadow a fellow security engineer during their on-call rotation

First 90 days:

  • Deliver a risk-classified SaaS and integration inventory with a clear remediation roadmap

  • Lead the first phase of identity infrastructure improvements, including access governance

  • Begin hardening core collaboration platforms with a focus on the highest-risk configurations

  • Actively participate in architecture design reviews with the team

  • Be the Tech Lead for a Corporate Security initiatives

  • Enhance incident response capabilities by participating in on-call rotation and post-incident activities

  • Create and maintain security documentation and runbooks

One Year Outlook

  • Identity infrastructure is rationalized and improved with most of access governance being automated

  • Clear security baseline for corporate devices with metrics tracking on compliance

  • SaaS governance is an ongoing, repeatable process - risks documented and accepted or remediated

  • Deception-based detection controls are live on endpoints in collaboration

  • Enhance security monitoring and anomaly detection

  • Support audits and ensure compliance with SOC 2, ISO 27xxx

  • Advocate for security best practices in enterprise system management

  • Lead security awareness campaigns and company-wide security events

Docker does not offer visa sponsorship for this role.

We use Covey as part of our hiring and / or promotional process for jobs in NYC and certain features may qualify it as an AEDT. As part of the evaluation process we provide Covey with job requirements and candidate submitted applications. We began using Covey Scout for Inbound on April 13, 2024.

Please see the independent bias audit report covering our use of Covey here.

Perks

  • Freedom & flexibility; fit your work around your life

  • Designated quarterly Whaleness Days plus end of year Whaleness break

  • Home office setup; we want you comfortable while you work

  • 16 weeks of paid Parental leave

  • Technology stipend equivalent to $100 net/month

  • PTO plan that encourages you to take time to do the things you enjoy

  • Training stipend for conferences, courses and classes

  • Equity; we are a growing start-up and want all employees to have a share in the success of the company

  • Docker Swag

  • Medical benefits, retirement and holidays vary by country

  • Remote-first culture, with offices in Seattle and Paris

Docker embraces diversity and equal opportunity. We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our company will be.

#LI-REMOTE

Remoto

Senior Security Engineer, Docker Desktop

Canada / England / United Kingdom / France / Germany / Italy / Portugal / Spain / United States
114 mil € - 187 mil €1m
Remoto

Senior Field Marketing Manager (EMEA)

England / United Kingdom / France / Germany / Ireland / Italy / Portugal / Spain
82 mil US$ - 117 mil US$1m
Remoto

Senior Sales Engineer, Strategic (EMEA - English)

England / United Kingdom / Germany / Italy / Spain / France / Ireland / Portugal
123 mil € - 175 mil €1m
Remoto

Global ISV & Technology Ecosystem Alliances Manager

England / United Kingdom / United States / France / Germany / Ireland / Italy / Portugal / Spain
166 mil € - 237 mil €1m
Remoto

Technical Account Manager (India)

Spain (Remote)
1m
Remoto

Senior People Partner, Engineering and Security (West Coast Preferred)

Spain (Remote)
1m
Remoto

Account Executive, Strategic (EMEA)

Spain (Remote)
1m
Remoto

Senior Software Engineer, Backend Systems (US East Coast)

Spain (Remote)
1m
Remoto

Staff Software Engineer, Backend Systems (US East Coast)

Spain (Remote)
1m
Remoto

Account Executive, Strategic, Federal (Civilian)

Spain (Remote)
1m
Remoto

Senior Security Engineer

Spain (Remote)
1m
Remoto

Senior Software Engineer, AI Developer Tools

Spain (Remote)
1m

🔐 Cybersecurity & Tech Talent Track - Empieza tu carrera con impacto | Septiembre 2026

Madrid
Nuevo

Cyber - Application Security Tester

Madrid
Nuevo

Senior - Security Architecture (Madrid) - MCS

Madrid
Nuevo

Consultor SAP Security & Control Access - Finco Tech

Madrid
Nuevo

Junior Cybersecurity Software Engineer

Getafe Area
1d

Data Center Security Specialist, DC Security team

Zaragoza, Aragon, ESP
2d

Data Center Security Manager, DC Security team

Zaragoza, Aragon, ESP
2d

Cybersecurity Manager / Delivery Lead

A Coruna, Canton Grande
2d

IOMadridDC_Infra Transformation Associate Manager Security Consultants_NATO

Madrid
5d

IOMadridDC_Infra Transformation Associate Manager Security Consultants_NATO Copy 01

Madrid
5d

Software Installation Engineer

Madrid - Home Based
Nuevo

Translational and Precision Medicine Lead 1

Europe - remote
Nuevo

Staff Software Engineer - Data Solutions & Measurement

Remote, REMOTE
Nuevo
Remoto

Sales Development Representative, German Speaking, EMEA

Remote- Spain
1d
Remoto

Creative & Marketing Freelancer Network

Remote - Europe
1d
Remoto

Agente Comercial Freelance – Retention & Recovery

Barcelona (Remote)
2d
Remoto

Expert Dutch and Belgian Comics

Remote - Europe
2d
Remoto

Senior Product Owner

Spain / ES-Remote / ES
3d

Junior Sales Representative - Oncology

Spain, Alcobendas Remote
4d

Total Rewards & Analytics Partner

Barcelona, CT (Remote)
4d
Remoto

Expert Asian Art & Antiques

Belgium; Berlin, Germany; France; Germany; Italy; Lisbon, Portugal; Netherlands; Poland; Portugal; Remote - Europe; Spain; United Kingdom
4d
Remoto

Expert AI Engineer

Spain / ES-Remote / ES
5d

Candidatura gestionada por Docker